Incident
Published 2026-08-19
Verified 2026-09-19

Quest Apartment Hotels: unauthorised access via a third-party provider

Quest identified unauthorised access on 17 August 2026 to a database through a vulnerability at a third-party service provider. Its statement says the incident is contained. Records involved are from before June 2025 and primarily names, email addresses and/or other contact details, with a small number of dates of birth. The company statement does not list payment card data and does not publish a count of affected records. Quest said it notified the OAIC and ACSC. Magazine reporting that put the figure around 1.5 million is secondary and unconfirmed by Quest.

Exploited in Australia?
unknown

Primary: Quest official statement ยท Information Age (secondary; unconfirmed headcount)

breaches supply chain australia